
EC-CouncilCertified Cybersecurity Technician
Domain 1Objective 1
Information Security Threats and Vulnerabilities CCT Practice Questions (Page 9)
Part of the Information Security Threats and Attacks domain, which makes up ~12% of our current practice bank.
47questions here
10free pages
7concepts
Questions 41–45
- 41
A company has a public-facing web application and an internal employee portal. The security team is conducting a risk assessment and wants to reduce the attack surface. Which of the following actions would most effectively reduce the attack surface?
Select an answer first - 42
A vulnerability assessment reveals that a web application has a SQL injection vulnerability that could allow an attacker to read the entire customer database. The application is internet-facing and is the company's primary revenue source. What is the most appropriate risk treatment?
Select an answer first - 43
Which type of threat actor is typically motivated by financial gain and uses sophisticated techniques to steal data or money?
Select an answer first - 44
A security analyst is conducting a vulnerability assessment of a new web application. The scan identifies several missing security headers and a potential SQL injection point. The analyst must prioritize which findings to report to management. Which approach best aligns with the purpose of a vulnerability assessment?
Select an answer first - 45
Which of the following best describes a phishing attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.